Class: Admin::ApiTokensController

Inherits:
BaseController
  • Object
show all
Defined in:
lib/generators/open_loam/install/templates/admin/api_tokens_controller.rb

Overview

Your own API tokens — creating and listing is scoped to current_actor, so there is no path to another user's credentials. Revoking is the exception: a manager owns offboarding, and a token that outlives someone's access is the thing offboarding is supposed to end.

Constant Summary

Constants included from Pagination

Pagination::PER_PAGE

Instance Method Summary collapse

Methods inherited from BaseController

skip_authorization!

Methods included from Pagination

#paginate

Instance Method Details

#create ⇒ Object



20
21
22
23
24
25
26
# File 'lib/generators/open_loam/install/templates/admin/api_tokens_controller.rb', line 20

def create
  token = api_tokens.create!(label: params[:label].presence || "API token")

  # The only time the plaintext exists: only its digest is stored, so this
  # screen is genuinely the last chance to copy it.
  redirect_to admin_api_tokens_path, flash: { token: token.token }
end

#destroy ⇒ Object



28
29
30
31
32
33
34
35
36
# File 'lib/generators/open_loam/install/templates/admin/api_tokens_controller.rb', line 28

def destroy
  # Tenant-scoped by the default scope, so another tenant's token is not
  # merely forbidden here — it is not findable.
  record = OpenLoam::ApiToken.find(params[:id])
  require_role!(:manager) unless record.user_id == current_actor.id

  record.destroy!
  redirect_to admin_api_tokens_path
end

#index ⇒ Object



13
14
15
16
17
18
# File 'lib/generators/open_loam/install/templates/admin/api_tokens_controller.rb', line 13

def index
  @records = api_tokens.order(created_at: :desc)
  # Only the label, owner and usage — never a token value, which no longer
  # exists in a readable form anyway.
  @tenant_records = manager? ? OpenLoam::ApiToken.where.not(user_id: current_actor.id).order(created_at: :desc) : []
end